index-546[.]hank-andrews-verusresearchs-net-s-account[.]workers[.]dev
“Worker threw exception | index-546.hank-andrews-verusresearchs-net-s-account.workers.dev | Cloudfla…”
index-546.hank-andrews-verusresearchs-net-s-account.workers.dev — Nicht bestätigt. Markenidentität: Cloudflare; Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 95/100. Registrar: Cloudflare Workers.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, index-546.hank-andrews-verusresearchs-net-s-account.workers.dev, is an active credential phishing threat designed to harvest user login credentials through fraudulent authentication interfaces. Analysis indicates the domain specifically targets individuals by impersonating legitimate services, likely leveraging social engineering tactics to deceive victims into submitting sensitive information. The domain is currently operational and has not been taken down despite security detections. Infrastructure analysis reveals the domain is registered through Cloudflare Workers and resolves to the IP address 188.114.96.3, located in Canada under Cloudflare, Inc. It was created on May 02, 2026, though this date may reflect automated registration processes rather than typical domain lifecycle timelines. The domain is flagged by 16 of 95 security vendors on VirusTotal, with a Let's Encrypt SSL certificate (serial number E7) providing HTTPS encryption to lend false legitimacy. It appears on one security blocklist, specifically PhishDestroy, and displays a Cloudflare Worker exception error, suggesting either misconfiguration or evasion attempts. The risk level for this domain is classified as high due to its active status, credential harvesting intent, and use of reputable hosting infrastructure to bypass initial scrutiny. Organizations and individuals are advised to block the domain at the network level and add the IP address 188.114.96.3 to firewall deny lists. Security teams should monitor for any attempts to access this domain from internal networks and conduct user awareness training to recognize phishing indicators, such as unusual subdomain structures and Cloudflare Worker-based URLs. Endpoint protection systems should be updated to include this domain in real-time threat intelligence feeds to prevent potential data breaches.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt